Back to skill

Security audit

Iran War Tracker V2

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its news-and-market monitoring purpose, but it embeds shared Jin10 credentials and copied tracking cookies that users should review before installing.

Review this skill before installing if you are uncomfortable with shared embedded provider credentials or fixed browser tracking identifiers being sent to Jin10. Use it only for its intended news and market-data reporting workflow, and avoid providing extra secrets beyond the documented provider API keys needed for market data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/jin10_mcp.py:20
Finding

Hard-Coded Jin10 Bearer Token

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/telegraphs.py:116
Finding

Hard-Coded Tracking Cookie and Persistent Device Identifier

Content
View full analysis
dict[str, Any]: headers = { "accept": "application/json, text/plain, */*", "accept-language": "zh-CN,zh;q=0.9,en;q=0.8,zh-TW;q=0.7", "content-type": "application/x-www-form-urlencoded", "cookie": "kind_g=%5B%223%22%5D; trend=1; Hm_lvt_522b01156bb16b471a7e2e6422d272ba=1774666362; HMACCOUNT=A36A0D3680700ED3; UM_distinctid=19d325bac30a26-0656d1d154b8928-26061f51-295d29-19d325bac3120d4; x-token=; env=prod; did=ebd69ed7-4348-4fdc-9cfe-35ddfaee42bc; CALENDAR_FAVOR_INDEX_LIST=%5B%5D; Hm_lpvt_522b01156bb16b471a7e2e6422d272ba=1774667075", "handleerror": "true", "origin": "https://www.jin10.com", "priority": "u=1, i", "referer": "https://www.jin10.com/", "sec-ch-ua": '"Chromium";v="146", "Not-A.Brand";v="24", "Google Chrome";v="146"', "sec-ch-ua-mobile": "?0", "sec-ch-ua-platform": '"Windows"', "sec-fetch-dest": "empty", "sec-fetch-mode": "cors", "sec-fetch-site": "same-site", "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36", "x-app-id": "bVBF4FyRTn5NJF5n", "x-version": "1.0.0", } ``` ### Technical Analysis The legacy Jin10 feed client contains a copied browser cookie string with analytics values and a persistent device identifier. Every execution sends these static identifiers to Jin10. The visible `x-token` cookie is empty, so the reviewed value does not demonstrate an authenticated user session. Nevertheless, the analytics and device identifiers are unnecessary for fetching public market flashes and cause unrelated installations to share one browser identity. This exceeds the minim ...[truncated 1448 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tainted flow: 'url' from os.environ.get (line 168, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/macro_monitor.py (reported line 92)May include surrounding context.

python
if elapsed < 12:
                    time.sleep(12 - elapsed)

                response = requests.get(url, timeout=30)
                cls._last_request_time = time.time()
                cls._request_count += 1

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hard-requires Chinese output regardless of the user's preference, which overrides user autonomy and can violate platform language-policy expectations. In practice, this can cause the agent to ignore or mishandle user requests made in other languages, reducing usability and potentially obscuring important safety-critical details for users who cannot read Chinese.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file-level documentation says this script is a simplified Jin10 MCP client for independently fetching quotes and flash news, implying it is a self-contained Jin10 utility. However, during MCP initialization the code reports clientInfo.name as 'iran-war-tracker-skill', which contradicts that stated identity and intent. This is an active documentation/intent mismatch rather than a mere omission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing natural language entirely in Chinese, including the module description and later printed test output, with no indication that language choice is configurable or intentionally limited to a Chinese-only audience. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire template is written in Chinese and structures the skill output exclusively in that language. Under the policy, a skill should not force a specific language or locale unless it offers opt-in or clearly documents a justified regional constraint, which this file does not do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction '默认用中文输出' forces a specific language behavior in natural-language guidance. Under the policy, locale or language constraints should either be user-selectable or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language instructions and descriptions in this file are exclusively Chinese, including the primary module docstring and usage guidance. Under the stated policy, forcing a specific language without opt-in can be a locale-policy issue when no alternative language or explicit justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs outbound HTTP requests to Alpha Vantage using requests.get, which transmits query parameters including the API key and usage metadata to an external service. Although network access is central to the script's purpose, there is no explicit user-facing notice at runtime or nearby warning comment disclosing that external services are contacted and credentials from environment variables are used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The call to pandas.read_csv with a remote HTTPS URL fetches data from a third-party service, but the script does not clearly warn users that backup mode causes additional outbound requests to Stooq. This is a user-disclosure gap because the operation reaches outside the local environment and may not be obvious from the invocation interface alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Jin10 request hard-codes an Accept-Language header preferring zh-CN, zh, and related locales. This is a natural-language policy concern because it imposes a specific language/locale choice in behavior without offering the user any option to select or override it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.